tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Attack-fix-verify
Makarand Bhaleraoabout 2 hours agoContributorJudging locked: Event build

Attack-fix-verify

An autonomous security agent that attacks a running API to find real vulnerabilities, uses an LLM to patch them, and crucially proves each fix by re-running the exact exploit before opening a GitHub pull request

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Watch demo video
Demo video
Watch demo video
Project description
I built an autonomous attack-fix-verify agent for AI-generated APIs, it attacks a running API like a real adversary over HTTP (IDOR, SQL injection, sensitive-data exposure, missing auth), confirms each bug by comparing the actual responses, then uses an LLM (Gemini) to propose a minimal patch for just the vulnerable handler and crucially, it doesn't trust the AI's fix, it trusts the re-attack: deterministic code re-runs the exact exploit and only marks a fix "verified" if the attack now fails, the legitimate good path still works, and the app still starts (else it retries up to 3× or flags for human review), after which it opens a GitHub pull request with the patch, auto-generated regression tests, and evidence. Semgrep is layered in as the static-analysis second opinion, it pre-scans the code for suspects (file/line/CWE), feeds those into the fix prompt, re-scans after patching, and most importantly cross-checks static vs. dynamic findings. On my app Semgrep caught only the SQL injection and missed the IDOR, data-exposure, and missing-auth logic bugs, which is exactly the point static analysis shows where code looks wrong, while the active attacker proves what's actually exploitable, so the two together are far stronger than either alone.
Tools used
  • SSemgrep
Project gallery
Project links
  • GitHub repository
  • Demo video
Tools used
  • SSemgrep